jseibert
Jun 17, 2020Nimbostratus
Need help extracting fields from Telemetry streamed JSON in Splunk
Hi,
We are streaming telemetry data from an F5 into Splunk, specifically client side bits in and out for all virtual servers. That part is working. In Splunk however I cannot extract or reference the field to get to the metrics.
I've tried various arrangements of
spath (index="f5_ltm"| spath "virtualServers{}.clientSide.bitsIn" output=n | table n)
but none yield any data from the search.
Any help or pointer is greatly appreciated.
Thank you.